Version control for agent sessions — the agit CLI plus skills/hooks/MCP wiring for Claude Code, Codex, OpenCode and Cursor. The AgentGit hub deploys separately.
LPM treats this as warn-only first-party agent extension lifecycle risk. Installation automatically delegates to a native binary's setup command. Its behavior is not available in this snapshot, so its agent configuration effects cannot be verified.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe manifest registers an automatic postinstall script.
package.jsonView on unpkg · L39This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
npm/postinstall.jsView on unpkgThe postinstall invokes the resolved native binary with the setup command unless an opt-out variable is set.
npm/postinstall.jsView on unpkg · L62The setup implementation is an opaque platform binary outside this package snapshot, so its configuration changes cannot be verified here.
npm/postinstall.jsView on unpkg · L36This report applies to @einsia/agent-git@0.2.6.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L40Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L40The manifest registers an automatic postinstall script.
package.jsonView on unpkg · L39The setup implementation is an opaque platform binary outside this package snapshot, so its configuration changes cannot be verified here.
npm/postinstall.jsView on unpkg · L36The postinstall invokes the resolved native binary with the setup command unless an opt-out variable is set.
npm/postinstall.jsView on unpkg · L62This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
npm/postinstall.jsView on unpkg